HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumActive
CVS Pharmacy, Inc.
bd_fc4af90e78d486c1 · schema v1 · pii pii-v1
Full breach record for CVS Pharmacy, Inc. →CVS Pharmacy, Inc. disclosed a breach affecting its CVSPhoto.com website, managed by third-party vendor PNI Digital Media. The incident occurred between June 19, 2014, and July 14, 2015, involving unauthorized access to PNI's systems. Affected data included names, payment card numbers, expiration dates, CVVs, addresses, phone numbers, emails, and login credentials. CVS disabled the site, engaged forensic investigators, and provided one year of free credit monitoring via Experian to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57763
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2015
- Raw hash
- 24c88413ee2e3ec01421a320e1b284af3a57be30ae7294f9c9c846c9bf5d01a6
Reporting entity
- Name
- CVS Pharmacy, Inc.norm: cvs pharmacy
- Domain
- cvs.com
Victim entity
- Name
- CVS Pharmacy, Inc.norm: cvs pharmacy
- Domain
- cvs.com
Incident
- Discovered
- Jul 1, 2015
- Materiality determined
- Sep 11, 2015
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.